Aklamator Woocommerce Promotion Security & Risk Analysis

wordpress.org/plugins/aklamator-woocommerce-promotion

Aklamator Woocommerce Promotion plugin will make widget and populate it with products from your Woocommerce web shop. Widget is showing product image, …

0 active installs v2.1.1 PHP + WP 3.0.1+ Updated Jan 26, 2018
ecommerceproduct-promotionshopwebshopwoocommerce
85
A · Safe
CVEs total0
Unpatched0
Last CVENever
Safety Verdict

Is Aklamator Woocommerce Promotion Safe to Use in 2026?

Generally Safe

Score 85/100

Aklamator Woocommerce Promotion has no known CVEs and is actively maintained. It's a solid choice for most WordPress installations.

No known CVEs Updated 8yr ago
Risk Assessment

The aklamator-woocommerce-promotion v2.1.1 plugin exhibits a generally strong security posture in several key areas, particularly regarding its limited attack surface. There are no identified AJAX handlers, REST API routes, shortcodes, or cron events, significantly reducing the opportunities for external interaction. The absence of known CVEs and a clean vulnerability history further contribute to a positive security impression. The plugin also exclusively uses prepared statements for its SQL queries, which is a critical best practice. However, there are notable concerns. The low percentage of properly escaped output (5%) is a significant weakness, indicating a high potential for Cross-Site Scripting (XSS) vulnerabilities where user-supplied data might be rendered without adequate sanitization. The presence of a single external HTTP request, while not inherently malicious, warrants attention as it could be a vector for information disclosure or further attacks if not handled securely. The lack of nonce checks and capability checks on entry points, coupled with the limited output escaping, suggests that authenticated users could potentially trigger unintended actions or inject malicious scripts.

In conclusion, while the plugin excels in minimizing its direct attack surface and adhering to secure database practices, the substantial risk of XSS due to poor output escaping and the potential for privilege escalation or unauthorized actions due to missing authorization checks are significant drawbacks. The single external HTTP request also adds a layer of risk that requires careful scrutiny. The plugin's strengths lie in its limited entry points and safe SQL handling, but these are overshadowed by the weaknesses in output sanitization and authorization, necessitating caution.

Key Concerns

  • Low percentage of properly escaped output
  • No nonce checks on entry points
  • No capability checks on entry points
  • External HTTP request without explicit context
Vulnerabilities
None known

Aklamator Woocommerce Promotion Security Vulnerabilities

No known vulnerabilities — this is a good sign.
Version History

Aklamator Woocommerce Promotion Release Timeline

v2.1.1Current
v2.1
v1.0.0
Code Analysis
Analyzed Mar 17, 2026

Aklamator Woocommerce Promotion Code Analysis

Dangerous Functions
0
Raw SQL Queries
0
0 prepared
Unescaped Output
42
2 escaped
Nonce Checks
0
Capability Checks
0
File Operations
0
External Requests
1
Bundled Libraries
1

Bundled Libraries

DataTables

Output Escaping

5% escaped44 total outputs
Attack Surface

Aklamator Woocommerce Promotion Attack Surface

Entry Points0
Unprotected0
WordPress Hooks 10
filterplugin_row_metaincludes\class-aklamatorWoo-pr.php:244
filterthe_contentincludes\class-aklamatorWoo-pr.php:254
actionatom_entryincludes\class-aklamatorWoo-pr.php:260
actionatom_entryincludes\class-aklamatorWoo-pr.php:262
actionatom_entryincludes\class-aklamatorWoo-pr.php:263
actionadmin_menuincludes\class-aklamatorWoo-pr.php:268
actionadmin_initincludes\class-aklamatorWoo-pr.php:269
actionadmin_enqueue_scriptsincludes\class-aklamatorWoo-pr.php:270
actionafter_setup_themeincludes\class-aklamatorWoo-pr.php:271
actionwidgets_initincludes\class-aklamatorWoo-pr.php:525
Maintenance & Trust

Aklamator Woocommerce Promotion Maintenance & Trust

Maintenance Signals

WordPress version tested4.9.29
Last updatedJan 26, 2018
PHP min version
Downloads2K

Community Trust

Rating0/100
Number of ratings0
Active installs0
Developer Profile

Aklamator Woocommerce Promotion Developer Profile

aklamator

7 plugins · 50 total installs

84
trust score
Avg Security Score
85/100
Avg Patch Time
30 days
View full developer profile
Detection Fingerprints

How We Detect Aklamator Woocommerce Promotion

Patterns used to identify this plugin on WordPress sites during automated security audits and web crawling.

Asset Fingerprints

Asset Paths
/wp-content/plugins/aklamator-woocommerce-promotion/aklamatorWoo-pr.php

HTML / DOM Fingerprints

JS Globals
AKLAWOO_PR_PLUGIN_NAMEAKLAWOO_PR_PLUGIN_DIRAKLAWOO_PR_PLUGIN_URL
Shortcode Output
<productphoto></productphoto><price></price>
FAQ

Frequently Asked Questions about Aklamator Woocommerce Promotion